cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1682
Views
0
Helpful
1
Replies

Switching VLANs Required in ISE CWA with Flex Connect local switching?

Dan Davis
Cisco Employee
Cisco Employee

 

ISE CWA with Flex Connect local switching. 

 

With this configuration does the client start off in one VLAN and then get switched to the local VLAN on the AP? I expect AAA override and CoA would be part of this? How does the client handle the re-dhcp - I expect there could be issues with some clients trying to switch their IP/VLAN. 

 

Is it possible to NOT have the client switch VLANs, maybe the client could pull an IP locally and then once the AUP or credentials are entered the ACL would be removed allowing them to switch data locally on the AP. 

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

No, this does not require VLAN change. In fact, we do not recommend VLAN changes for CWA.

ExpandBranch Office Wireless LAN Design - BRKEWN-2016 has some details in Slides 76 ~ 86 on BYOD, which works similarly to CWA, in terms of configurations in WLC.

Also see Central Web Authentication with FlexConnect APs on a WLC with ISE Configuration Example - Cisco

View solution in original post

1 Reply 1

hslai
Cisco Employee
Cisco Employee

No, this does not require VLAN change. In fact, we do not recommend VLAN changes for CWA.

ExpandBranch Office Wireless LAN Design - BRKEWN-2016 has some details in Slides 76 ~ 86 on BYOD, which works similarly to CWA, in terms of configurations in WLC.

Also see Central Web Authentication with FlexConnect APs on a WLC with ISE Configuration Example - Cisco